Skip to main content
All playbooks
Playbook

Your telehealth platform reported a breach

Video, audio, transcripts, chat, and screen-shared documents may have been exposed. Consent, recording, and OCR scope all matter — and patients react more strongly to telehealth breaches because the visit feels personal.

Last reviewed: May 2026

The first hour

  1. 1Get the vendor's incident notification in writing — email or letter, not a phone call. It must include discovery date, breach window, data categories, patient counts attributable to your practice, and the vendor's notification posture.
  2. 2Pause any telehealth visits scheduled in the next 24 hours unless the vendor has confirmed the platform is secure. The decision to resume is yours.
  3. 3Pull the BAA. Note the incident-notification clock, patient-notification responsibility assignment, and recording-handling clauses.
  4. 4Inventory affected sessions: pull the visit log from the platform for the breach window. Flag sessions involving screen-shared PHI, recorded interpreter services, or clinical content in chat.
  5. 5Notify your cyber insurance carrier with the vendor's written notification attached. Telehealth breaches often qualify under both cyber and professional-liability lines.
  6. 6Decide whether to notify patients on your own initiative or wait for the vendor. Patients are calmer hearing from their doctor's office than from a vendor they may not recognize.

Evidence to preserve

What not to delete, what to screenshot, what to log. Do this before recovery starts — most of it disappears as soon as systems are rebuilt.

  • Vendor's written breach notification (email + PDF) with timestamps.
  • Your signed BAA and any amendments.
  • Visit log export from the platform covering the breach window.
  • List of sessions where PHI was screen-shared or exchanged in chat.
  • Entry in your security incident log — required under the HIPAA Security Rule and the most common documentation gap OCR cites in small-practice investigations.

The HIPAA breach clock

The breach-notification clock starts at discovery. Federal HHS deadline is 60 days; many states are faster.
HHS / patient (federal)
October 27, 2026
60 days from discovery
CA / FL / others
September 27, 2026
30-day state floor
NY / others
October 12, 2026
45-day state floor

Breaches affecting 500+ patients in a single state are reported to HHS and media immediately, not within 60 days. Confirm state-specific timelines with counsel.

Regulator contacts

Frequently asked

Did the vendor record our sessions?+

It depends on the platform and your configuration. Three questions shape your notification scope: did the vendor record sessions; are the recordings in the breach scope; and did you ever screen-share PHI (labs, imaging, an EHR view) during sessions. Get written answers from the vendor before you draft the letter.

Whose obligation is patient notification — ours or the vendor's?+

By default, the covered entity. Some BAAs shift it to the BA. Even when the BA notifies, OCR can still come back to you. If the vendor will notify, confirm in writing that they have started and ask for the language they will use.

Is our telehealth consent enough?+

Often not. Many practices use a generic in-person consent. Telehealth consent should specifically address recording (whether, where stored, retention), interpreter participation, and the patient's right to refuse telehealth. Update it as part of this incident's remediation.

Need to walk through this with someone?

Free first call. If we're the right fit, we'll tell you. If we're not, we'll tell you that too.

This page is general guidance, not legal advice. Reading it does not create a Business Associate relationship with HackFirstAid. See scope of use.

Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.